The Metasploit Framework - Spencer McIntyre

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • number6
    404 Image not found
    • Apr 2019
    • 2172

    #1

    The Metasploit Framework - Spencer McIntyre

    The Metasploit Framework

    Friday August 11, 10:00 – 11:55, Committee Boardroom, Forum

    Spencer McIntyre

    Active Directory is the foundation of the infrastructure for many organizations. As of 2023, Metasploit has added a wide range of new capabilities and attack workflows to support Active Directory exploitation. This DEF CON demonstration will cover new ways to enumerate information from LDAP, attacking Active Directory Certificate Services (AD CS), leveraging Role Based Constrained Delegation, and using Kerberos authentication. The Kerberos features added in Metasploit 6.3 will be a focal point. The audience will learn how to execute multiple attack techniques, including Pass-The-Ticket (PTT), forging Golden/Silver Tickets, and authenticating with AD CS certificates. Finally, users will see how these attack primitives can be combined within Metasploit to streamline attack workflows with integrated ticket management. The demonstration will also highlight inspection capabilities that are useful for decrypting traffic and tickets for debugging and research purposes.

    Spencer McIntyre is a Security Research Manager at Rapid7, where he works on the Metasploit Framework. He has been contributing to Metasploit since 2010, a committer since 2014, and a core team member at Rapid7 since 2019. Previously, Spencer worked at a consulting firm working with clients from various industries, including healthcare, energy, and manufacturing. He is an avid open source contributor and Python enthusiast.

    Audience: Offense


    Starts
    August 11, 2023 10:00
    Ends
    August 11, 2023 11:55
    Location
    Committee Boardroom, Forum
  • zeroSteiner
    Member
    • Jul 2023
    • 1

    #2
    Just a little preview of what I'll be demoing on Friday:

    Click image for larger version

Name:	image.png
Views:	544
Size:	582.7 KB
ID:	246468Quite a bit of the functionality I'll cover is new this year in version 6.3. The release blog outlines quite a bit of the Kerberos, and AD CS related content that I'll be demoing.

    Metasploit can be found on GitHub at rapid7/metasploit-framework. Additionally, there are dedicated sections in the documentation for AD CS attacks, Kerberos Authentication, including RBCD attacks.

    If you have any questions before or after the demo, be sure to ask them here, and I'll see you all in Las Vegas!

    Comment

    Working...